Hackers use fake Adobe and Zoom updates to load malware onto victim devices — here’s what to look out for

Emerging Threats in Cybersecurity

In a recent revelation, Securonix Threat Research has identified a sophisticated cyber campaign known as SMOKE#SCREEN. This initiative employs deceptive tactics to lure users into installing weaponized versions of ScreenConnect, a legitimate remote monitoring and management (RMM) software. The attackers cleverly disguise their malicious intent by utilizing fake update notifications for popular applications such as Zoom and Adobe, alongside a variety of counterfeit business documents, including system maintenance tools and invoices.

The implications of this campaign are significant, as it allows attackers to gain persistent remote access to victims’ systems. By evolving their tactics, these cybercriminals are able to disable security protections and exploit trusted services like Dropbox and Cloudflare to facilitate the delivery of their malicious payloads.

Victims have been reported across both Windows and macOS platforms, highlighting the widespread nature of this threat. In light of these developments, businesses are strongly encouraged to verify updates through official channels and to implement training for staff on the dangers of unexpected software installations. This proactive approach is essential in safeguarding against such insidious attacks.

Tech Optimizer
Hackers use fake Adobe and Zoom updates to load malware onto victim devices — here's what to look out for